2025 CVE Vulnerabilities
45,325 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-60794 | MEDIUM | 6.5 | 0.2% | Nov 20, 2025 | Session tokens and passwords in couch-auth 0.21.2 are stored in JavaScript objects and remain in memory without explicit... |
| CVE-2025-5092 | MEDIUM | 6.4 | 0.2% | Nov 20, 2025 | Multiple plugins and/or themes for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled ligh... |
| CVE-2025-41076 | MEDIUM | 6.5 | 0.2% | Nov 20, 2025 | In version 6.13.0 of LimeSurvey, any external user can cause a 500 error in the survey system by sending a malformed ses... |
| CVE-2025-40605 | MEDIUM | 5.3 | 0.3% | Nov 20, 2025 | A Path Traversal vulnerability has been identified in the Email Security appliance allows an attacker to manipulate file... |
| CVE-2025-13469 | MEDIUM | 4.8 | 0.2% | Nov 20, 2025 | A security vulnerability has been detected in Public Knowledge Project omp and ojs 3.3.0/3.4.0/3.5.0. Impacted is an unk... |
| CVE-2025-13450 | MEDIUM | 5.4 | 0.2% | Nov 20, 2025 | A vulnerability was determined in SourceCodester Online Shop Project 1.0. Impacted is an unknown function of the file /s... |
| CVE-2025-13443 | MEDIUM | 6.5 | 0.2% | Nov 20, 2025 | A vulnerability was detected in macrozheng mall up to 1.0.3. Affected by this issue is the function delete of the file /... |
| CVE-2025-12778 | MEDIUM | 5.3 | 0.2% | Nov 20, 2025 | The Ultimate Member Widgets for Elementor – WordPress User Directory plugin for WordPress is vulnerable to unauthorized ... |
| CVE-2025-12502 | MEDIUM | 6.8 | 0.2% | Nov 20, 2025 | The attention-bar WordPress plugin through 0.7.2.1 does not sanitize and escape a parameter before using it in a SQL sta... |
| CVE-2025-13415 | MEDIUM | 5.4 | 0.2% | Nov 19, 2025 | A vulnerability was identified in icret EasyImages up to 2.8.6. This affects an unknown part of the file /app/upload.php... |
| CVE-2025-58181 | MEDIUM | 5.3 | 0.5% | Nov 19, 2025 | SSH servers parsing GSSAPI authentication requests do not validate the number of mechanisms specified in the request, al... |
| CVE-2025-47914 | MEDIUM | 5.3 | 0.5% | Nov 19, 2025 | SSH Agent servers do not validate the size of messages when processing new identity requests, which may cause the progra... |
| CVE-2025-13412 | MEDIUM | 6.1 | 0.2% | Nov 19, 2025 | A vulnerability was determined in Campcodes Retro Basketball Shoes Online Store 1.0. Affected by this issue is some unkn... |
| CVE-2025-13147 | MEDIUM | 5.3 | 0.2% | Nov 19, 2025 | Server-Side Request Forgery (SSRF) vulnerability in Progress MOVEit Transfer.This issue affects MOVEit Transfer: before ... |
| CVE-2025-63214 | MEDIUM | 6.5 | 0.3% | Nov 19, 2025 | An issue was discovered in bridgetech VBC Server & Element Manager, firmware version 6.5.0-10 , 6.5.0-9, allowing unauth... |
| CVE-2025-63212 | MEDIUM | 6.5 | 0.3% | Nov 19, 2025 | GatesAir Flexiva-LX devices on firmware 1.0.13 and 2.0, including models LX100, LX300, LX600, and LX1000, expose sensiti... |
| CVE-2025-51662 | MEDIUM | 5.4 | 0.1% | Nov 19, 2025 | A stored cross-site scripting (XSS) vulnerability is found in the text sharing feature of FileCodeBox version 2.2 and ea... |
| CVE-2025-36371 | MEDIUM | 6.5 | 0.2% | Nov 19, 2025 | IBM i 7.2, 7.3, 7.4, 7.5, and 7.6 are impacted by obtaining an information vulnerability in the database plan cache impl... |
| CVE-2025-65100 | MEDIUM | 6.9 | 0.3% | Nov 19, 2025 | Isar is an integration system for automated root filesystem generation. In versions 0.11-rc1 and 0.11, defining ISAR_APT... |
| CVE-2025-64759 | MEDIUM | 6.1 | 0.3% | Nov 19, 2025 | Homarr is an open-source dashboard. Prior to version 1.43.3, stored XSS vulnerability exists, allowing the execution of ... |
| CVE-2025-63211 | MEDIUM | 6.1 | 0.2% | Nov 19, 2025 | Stored cross-site scripting vulnerability in bridgetech VBC Server & Element Manager, firmware versions 6.5.0-9 thru 6.5... |
| CVE-2025-65089 | MEDIUM | 6.5 | 0.3% | Nov 19, 2025 | XWiki Remote Macros provides XWiki rendering macros that are useful when migrating content from Confluence. Prior to ver... |
| CVE-2025-65032 | MEDIUM | 6.5 | 0.2% | Nov 19, 2025 | Rallly is an open-source scheduling and collaboration tool. Prior to version 4.5.4, an Insecure Direct Object Reference ... |
| CVE-2025-65031 | MEDIUM | 6.5 | 0.2% | Nov 19, 2025 | Rallly is an open-source scheduling and collaboration tool. Prior to version 4.5.4, an improper authorization flaw in th... |
| CVE-2025-65028 | MEDIUM | 6.5 | 0.2% | Nov 19, 2025 | Rallly is an open-source scheduling and collaboration tool. Prior to version 4.5.4, an insecure direct object reference ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now